Hunt RAG Vector
elementalsouls/Claude-BugHunter
Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from…
Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…
$ npx skills add microsoft/power-platform-skills --skill manage-headers -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft/power-platform-skills manage-headers --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/power-pages/skills/manage-headers .claude/skills/manage-headers && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "manage-headers" agent skill from https://github.com/microsoft/power-platform-skills/tree/main/plugins/power-pages/skills/manage-headers into .claude/skills/manage-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "manage-headers", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft/power-platform-skills/tree/main/plugins/power-pages/skills/manage-headersType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft/power-platform-skills --skill manage-headers -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft/power-platform-skills manage-headers --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/power-pages/skills/manage-headers .agents/skills/manage-headers && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "manage-headers" agent skill from https://github.com/microsoft/power-platform-skills/tree/main/plugins/power-pages/skills/manage-headers into .agents/skills/manage-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "manage-headers", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/power-platform-skills --skill manage-headers -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft/power-platform-skills manage-headers --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/power-pages/skills/manage-headers .cursor/skills/manage-headers && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "manage-headers" agent skill from https://github.com/microsoft/power-platform-skills/tree/main/plugins/power-pages/skills/manage-headers into .cursor/skills/manage-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "manage-headers", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft/power-platform-skills.git --path plugins/power-pages/skills/manage-headers--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft/power-platform-skills --skill manage-headers -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft/power-platform-skills manage-headers --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/power-pages/skills/manage-headers .gemini/skills/manage-headers && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "manage-headers" agent skill from https://github.com/microsoft/power-platform-skills/tree/main/plugins/power-pages/skills/manage-headers into .gemini/skills/manage-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "manage-headers", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft/power-platform-skills manage-headersInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft/power-platform-skills --skill manage-headers -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/power-pages/skills/manage-headers .github/skills/manage-headers && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "manage-headers" agent skill from https://github.com/microsoft/power-platform-skills/tree/main/plugins/power-pages/skills/manage-headers into .github/skills/manage-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "manage-headers", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/power-platform-skills --skill manage-headers -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft/power-platform-skills manage-headers --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/power-pages/skills/manage-headers .opencode/skills/manage-headers && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "manage-headers" agent skill from https://github.com/microsoft/power-platform-skills/tree/main/plugins/power-pages/skills/manage-headers into .opencode/skills/manage-headers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "manage-headers", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
manage-headersInspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…
Manage Headers is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related site settings. Identifies gaps and walks the user through fixes. Use when the user wants to review headers, fix CSP errors, allow embedding in another site, control cross-origin access, harden cookie settings, or asks "are my browser settings safe?", "fix my CSP", "set up CORS" — even if they only mention a specific…
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/commands.md`, `references/headers-reference.md` and `scripts/transform-headers.js`).
It sits in AI & LLM Engineering, covering Secure coding and Embeddings. The repository describes itself as: A plugin marketplace for GitHub Copilot and other AI agents that provides Power Platform development plugins, including reusable skills, agents, and commands for building and… The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 5ef4e4f. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBashGlobGrepAskUserQuestionTaskCreateTaskUpdateTaskListFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Manage Headers loads about 3k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 1,393 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Write, Edit, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskListAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from microsoft/power-platform-skills at commit 5ef4e4f, republished under its MIT licence (© microsoft). 1,393 words, ~3,023 tokens.
.claude/skills/manage-headers/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Plugin check: Run
node "${PLUGIN_ROOT}/scripts/check-version.js"— if it outputs a message, show it to the user before proceeding.
Inspect and configure the HTTP security headers for a Power Pages site. Headers are configured as HTTP/* site settings stored in .powerpages-site/site-settings/ YAML files.
Initial request: $ARGUMENTS
.yml file in .powerpages-site/site-settings/. The file name uses - instead of / (e.g., HTTP/X-Frame-Options → http-x-frame-options.sitesetting.yml).HTTP/Strict-Transport-Security — the runtime does not recognize it and the setting has no effect.HTTP/* header emission. Verify headers in an incognito tab, not the studio preview.script-src contains 'nonce', the runtime replaces it per-request with 'nonce-<random>' and auto-hashes inline event handlers. Scripts created dynamically via document.createElement do NOT receive the nonce.SameSite=None requires HTTPS. The runtime sets Secure on every cookie over HTTPS automatically.* is auto-specialized. The runtime replaces * per-request with the specific requesting Origin — the browser sees a single-origin header, not a wildcard.Create tasks in four groups. Mark each in_progress when starting, completed when done.
| Group | When to create | Tasks |
|---|---|---|
| 1 | At start | Check prerequisites |
| 2 | After prerequisites pass | Inspect current headers · Assess and plan (skip "Assess and plan" in review mode) |
| 3 | After user approves changes | Apply changes (skip in review mode OR if no changes were accepted) |
| 4 | After apply or assess | Summarize (always) |
Use Glob to find **/powerpages.config.json. If $ARGUMENTS contains --review <out-dir>, remember the output directory — Steps 3–4 are skipped and Step 5 writes JSON only.
Check that .powerpages-site/site-settings/ exists. If not, the site has not been deployed yet — tell the user and recommend /deploy-site. Stop.
Use Glob to find all *.yml files in .powerpages-site/site-settings/. Use Read to read each file and extract the name and value fields. Identify all settings with an HTTP/ prefix — these are the configured headers.
Compare against the recognized header catalogue in references/headers-reference.md. For each header in the catalogue:
For CSP specifically: if HTTP/Content-Security-Policy is present, scan the project's source files using Glob + Read to find external URLs and check whether they are covered by the policy. Identify the site's cloud environment via pac auth who to determine the correct Power Pages runtime host (see headers-reference.md § "Power-Pages-runtime sources a CSP must allow").
Skip in review mode.
MUST use plain language only. Never lead with words like CSP, CORS, HSTS, or MIME sniffing — explain using everyday language:
| Header concept | Plain-language name |
|---|---|
| Content-Security-Policy | "which scripts and resources the browser is allowed to load" |
| X-Frame-Options / frame-ancestors | "whether other websites can put your site inside a frame" |
| X-Content-Type-Options | "stop the browser from guessing file types" |
| CORS headers | "which other websites can call your site's data" |
| SameSite cookies | "when the browser sends your sign-in cookie" |
Read references/headers-reference.md for recommended values and guidance. Present the most important gaps first — headers that are missing or misconfigured relative to the recommended values.
<!-- gate: manage-headers:3.per-finding | category=plan | cancel-leaves=nothing -->
🚦 Gate (plan · manage-headers:3.per-finding): Per-finding loop — for each header gap, prompt accept / customize / skip. Fires PER FINDING in the loop; skipped findings leave the header at its current value, accepted/customized findings get an Edit / create-script call in Phase 4.
Trigger: Phase 3 entry has tallied header gaps against
references/headers-reference.md. Why we ask: Auto-accepting can apply CSP/CORS values that break the site (legitimate scripts blocked, third-party widgets refused); auto-skipping leaves the site missing important headers. Cancel leaves: Nothing — Phase 4's Edit / create-script call only fires on accepted findings.
For each finding, present via AskUserQuestion:
Do NOT present all headers at once — present the important gaps first. For headers already set to recommended values, mention them in the summary without requiring action.
When the user needs a CSP (missing or incomplete), compose one using:
'nonce' keyword for inline scriptsWhen reviewing an existing CSP, validate:
Present the composed or corrected CSP for review. Recommend starting in report-only mode (HTTP/Content-Security-Policy-Report-Only) before enforcing.
Skip in review mode.
For existing settings: use Edit on the YAML file directly — change the value field.
For new settings: use the shared create script:
node "${PLUGIN_ROOT}/scripts/create-site-setting.js" \
--projectRoot "<PROJECT_ROOT>" \
--name "<setting-name>" \
--value "<value>" \
--description "<description>"See references/commands.md for details.
After all changes are applied, offer to deploy: "Ready to deploy these changes? They take effect after the next deploy." If yes, invoke /deploy-site.
First, read the configured HTTP/* site settings (from Step 2 — you already have them). Then write <REVIEW_DIR>/header-annotations.json with a plain-language description for each header and, when the configured value has a genuine issue (missing critical directive, weak value), a suggested fix. The transform script no longer hardcodes header descriptions — they come from you.
{
"headers": {
"HTTP/<HeaderName>": { "description": "What this header does, in plain language.", "fix": "Optional fix if the configured value has a genuine issue." }
}
}Use references/headers-reference.md for authoritative descriptions and validation rules. Surface a fix only when the value has a real problem — do not editorialize on every header.
Then run the transform:
node "${PLUGIN_ROOT}/skills/manage-headers/scripts/transform-headers.js" \
--projectRoot "<PROJECT_ROOT>" \
--annotations "<REVIEW_DIR>/header-annotations.json"Write the stdout to <REVIEW_DIR>/manage-headers.json and stop. The transform emits { status, findings, details }; the orchestrating skill handles presentation.
Skip in review mode.
Plain-language summary: what was changed, what gaps remain, and what is already well-configured.
Reference:
${PLUGIN_ROOT}/references/skill-tracking-reference.mdUse
--skillName "ManageHeaders".
If a natural follow-up exists based on findings, suggest it. If no meaningful follow-up exists, end the skill.
cross-origin when unsure.preview only on options that modify a setting value. Do not add to informational choices.https: wildcards in CSP directives — list specific hosts instead./deploy-site after applying changes.references/headers-reference.md — recognized header catalogue, recommended values, CSP composition rules, runtime sources. Read before Step 2 (inspect) and Step 3 (assess) in interactive mode.references/commands.md — shared create-site-setting.js usage. Read at Step 4 (apply) when creating new settings.© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in plugins/power-pages/skills/manage-headers of microsoft/power-platform-skills.
Open the folder on GitHubat commit 5ef4e4f
Manage Headers next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Manage Headers this skillmicrosoft/power-platform-skills | 967 | — | ~3k | Automated safety check: Notes | MIT | |
| Hunt RAG Vectorelementalsouls/Claude-BugHunter | 4.8k | — | ~2.6k | Automated safety check: Pass | MIT | |
| Chroma Vector DatabaseOrchestra-Research/AI-Research-SKILLs | 13k | 8 repos | ~2.3k | Automated safety check: Pass | MIT | |
| CLIP Image-Text MatchingOrchestra-Research/AI-Research-SKILLs | 13k | 8 repos | ~1.7k | Automated safety check: Pass | MIT | |
| SageMaker Serving Image Selectionhuggingface/skills | 11k | 1 repos | ~4.6k | Automated safety check: Pass | Apache-2.0 | |
| Codebase Managementgiancarloerra/SocratiCode | 3.3k | 1 repos | ~1.8k | Automated safety check: Pass | AGPL-3.0 |
elementalsouls/Claude-BugHunter
Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from…
Orchestra-Research/AI-Research-SKILLs
Shows how to store documents and embeddings in Chroma, query them by similarity with metadata filters, and persist them to disk for RAG and semantic search projects.
Orchestra-Research/AI-Research-SKILLs
Explains OpenAI's CLIP model for zero-shot image classification, image-text similarity, semantic image search and content moderation, with install steps and code patterns.
huggingface/skills
Chooses the right serving container and current image URI for deploying a Hugging Face model to a SageMaker endpoint, preferring Hugging Face images over generic ones.
giancarloerra/SocratiCode
Set up, index, and manage SocratiCode codebase indexing. An agent skill from giancarloerra/SocratiCode.
huggingface/skills
Routes a sentence-transformers training task to the right model type and required reference docs and example scripts, covering bi-encoders, rerankers, sparse and multi-vector models.
microsoft/power-platform-skills
Inspects and configures the web application firewall (WAF) in front of a Power Pages production site.
microsoft/power-platform-skills
Scans a Power Pages site project for security issues in source code and dependencies.
microsoft/power-platform-skills
Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary.
microsoft/power-platform-skills
Creates Dataverse tables, columns, and relationships for a Power Pages site based on a data model proposal.
microsoft/power-platform-skills
Creates, edits, and manages Power Pages Server Logic files — server-side JavaScript that runs securely on the Power Pages runtime.
microsoft/power-platform-skills
Activates and provisions a Power Pages website in a Power Platform environment via the Power Platform REST API.
Categories
Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…. Manage Headers is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related site settings.
Manage Headers fits situations like: the user wants to review headers; allow embedding in another site; control cross-origin access; harden cookie settings.
Run `npx skills add microsoft/power-platform-skills --skill manage-headers -a claude-code`. Or copy the skill folder (plugins/power-pages/skills/manage-headers in microsoft/power-platform-skills) into .claude/skills/manage-headers in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft/power-platform-skills --skill manage-headers -a codex`. Or copy the skill folder (plugins/power-pages/skills/manage-headers in microsoft/power-platform-skills) into .agents/skills/manage-headers in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/power-platform-skills --skill manage-headers -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/manage-headers, .gemini/skills/manage-headers, .github/skills/manage-headers and .opencode/skills/manage-headers in your project.
Going by SKILL.md and its folder, Manage Headers needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Manage Headers is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Manage Headers: Hunt RAG Vector (elementalsouls/Claude-BugHunter, 4.8k stars), Chroma Vector Database (Orchestra-Research/AI-Research-SKILLs, 13k stars), CLIP Image-Text Matching (Orchestra-Research/AI-Research-SKILLs, 13k stars) and SageMaker Serving Image Selection (huggingface/skills, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/power-platform-skills, which has 967 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on October 6, 2026.
Source: microsoft/power-platform-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.